# Stuck on adding RFXcom on a second Pi - permission denied

**URL:** <https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041>\
**Category:** General\
**Tags:** docker\
**Created:** [29 December 2025 14:37 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041 "2025-12-29T14:37:51Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mastiff](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Mastiff](https://discourse.nodered.org/u/Mastiff)\
**Post date:** [29 December 2025 14:37 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/1 "2025-12-29T14:37:51Z")

</div>

I am trying to add an RFXtrx to a Pi that hasn't had one before. But I keep getting this:

`[rfxcom] on /dev/ttyUSB0 - Error: Permission denied, cannot open /dev/ttyUSB0`

This is my Docker Compose file:

```auto
services:
  node-red:
    build:
      dockerfile_inline: | 
        FROM nodered/node-red:4.0.9-debian
        USER root
        RUN apt-get update \
          && apt-get install -y --no-install-recommends iputils-ping sshpass openssh-client
        USER node-red
    container_name: Node-RED
    privileged: true
    restart: no
    group_add:
        - "20"
    environment:
      - TZ=Europe/Oslo

    network_mode: host 
    devices:
      - /dev/serial/by-id/usb-RFXCOM_RFXtrx433_A12VLOW7-if00-port0:/dev/ttyUSB0
    volumes:
      - /media/pi/Docker/Docker-Compose/Node-RED/Data:/data
      - /media/pi/Docker/Docker-Compose:/home/pi/Docker-Compose:ro
      - type: bind
        source: /home/pi/Node-RED-omstarter.txt
        target: /home/pi/Node-RED-omstarter.txt
      - type: bind
        source: /home/pi/.ssh/known_hosts
        target: /usr/src/node-red/.ssh/known_hosts

```

I have checked that ttyUSB0 excists in the container with `docker exec -it Node-RED bash` and `ls` in the `dev` directory. So it seems that Node-RED within the container isn't allowed to use the USB0. I have three other Pi's running the same setup, and they work, but they have been through lots of generations of both Pi's, Pi OS and Node-RED, so I can't find out what I did different there. I ran `sudo usermod -aG docker pi` in the hope that it would change anything, which it didn't. So my limited understanding has reached it's end. I hope somebody can help me with this one.

---

<div class="post-metadata">

**Author:** ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)\
**Post date:** [29 December 2025 14:46 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/2 "2025-12-29T14:46:00Z")

</div>

> [@Mastiff](#):
>
> /dev/ttyUSB0 - Error: Permission denied

That is because the user running Node-RED does not have permission to access the USB dev's.

![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/4/a/4a8a56f2f965778f49ba4ed9bde6160143cd2466.png)

Note how they belong to root but are given access to group `dialout`.

To fix this, simply add the Node-RED user to the `dialout` group.

But while you are there, don't use the `ttyUSBn` dev, you should use the more explicit UDEV entry. This will save you when Linux decides to randomly change the usb number on you:

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/e/1/e12feb293adc65bbb30c7f8a659031bd5a30417d.png)

---

<div class="post-metadata">

**Author:** ![Mastiff](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Mastiff](https://discourse.nodered.org/u/Mastiff)\
**Post date:** [29 December 2025 14:54 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/3 "2025-12-29T14:54:11Z")

</div>

Thanks for answering! Actually the user running Node-RED has dialout, but you got me on the right track. The USB0 is only `root` and `plugdev`, not `dialout`!

And yes, I am actually using this for the device, I just simplified the Docker Compose file:

`- /dev/serial/by-id/usb-RFXCOM_RFXtrx433_A12VLOW7-if00-port0:/dev/ttyUSB0`

So now I only have to find out why the `dialout` group does not have access to USB0. That should be googleable. 😁

---

<div class="post-metadata">

**Author:** ![Mastiff](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Mastiff](https://discourse.nodered.org/u/Mastiff)\
**Post date:** [29 December 2025 15:10 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/4 "2025-12-29T15:10:33Z")

</div>

OK, not so easy... I tried creating an udev rule like this:

`sudoedit /etc/udev/rules.d/50-myusb.rules`

```auto
KERNEL=="ttyUSB[0-9]*",MODE="0666"
KERNEL=="ttyACM[0-9]*",MODE="0666"

```

and adding pi to the plugdev group:

`sudo usermod -a -G plugdev pi`

none of them helped. And yes, I did reboot after each time.

---

<div class="post-metadata">

**Author:** ![Mastiff](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Mastiff](https://discourse.nodered.org/u/Mastiff)\
**Post date:** [29 December 2025 15:27 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/5 "2025-12-29T15:27:11Z")

</div>

Finally! I of course had to add the group `plugdev` to the docker compose file:

```auto
    group_add:
        - "46"

```

Up and running! 😃

---

<div class="post-metadata">

**Author:** ![Jibun-no-Kage](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/jibun-no-kage/32/99316_2.png) [@Jibun-no-Kage](https://discourse.nodered.org/u/Jibun-no-Kage)\
**Post date:** [31 December 2025 04:48 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/6 "2025-12-31T04:48:06Z")

</div>

@Mastiff, so the custom udev rules still applicable? Or not? You have just opened access to all containers that may exist? The udev rules are system wide? Or container specific?

---

<div class="post-metadata">

**Author:** ![Mastiff](https://avatars.discourse-cdn.com/v4/letter/m/ee7513/32.png) [@Mastiff](https://discourse.nodered.org/u/Mastiff)\
**Post date:** [31 December 2025 20:03 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/7 "2025-12-31T20:03:03Z")

</div>

I deleted that one, it wasn't necessary. It was adding the container to the plugdev group that did it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [14 January 2026 20:03 UTC](https://discourse.nodered.org/t/stuck-on-adding-rfxcom-on-a-second-pi-permission-denied/100041/8 "2026-01-14T20:03:26Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
